Everything draws on the same estate.
Ten areas, one agent, one permission model. What you define once as a rule applies to monitoring, software, patches and automations alike.
checks out of the box, at no extra cost
operating systems with one agent: Windows, Linux, macOS
ready-made report templates
device types, monitorable without an agent too
What the platform covers
Each area is useful in its own right — together they replace the toolbox.
Monitoring & alerting
Over 100 ready-made checks for servers, clients, network and security.
Over 100 checks included, covering hardware, network, security and services
Backup monitoring for Veeam, Acronis, Cove, Altaro, Arcserve, Synology, Windows Server Backup and more
Agentless monitoring via SNMP v3, TR-064 and the VMware API — switches, firewalls, UPS units, printers, NAS, ESXi
Custom checks in PowerShell, Bash or as an SNMP query, including a live test against a real device
Alert escalation based on failure rate rather than every single blip — fewer false alarms
TV mode as a wallboard for the service desk
Patch management
Staged rollout with deployment rings, approvals and maintenance windows.
Deployment rings: test group first, then the wider estate — each ring with its own maintenance window and device rules
Automatic promotion to the next ring only once a defined success rate is met
Approval workflow per patch cycle: approve everything, critical only, reject or enforce
Exclusions by update ID, KB number or category, including known problem updates
Restart control with user-initiated deferral instead of a forced reboot in the middle of the working day
Update catalogue with severity filter and vendor notes
Software deployment
Supply Windows, macOS and Linux from a single interface.
One process for all three operating systems: Windows, macOS and Linux — no separate tooling per platform
octoja uses the package sources already present on each system
Identify outdated software per device and update it selectively or across the estate
Custom packages with versioned installation steps and a test installation before rollout
Software kiosk on the endpoint: users install approved applications themselves
Software inventory across the entire estate, including licence key capture
Automation
Rules instead of clicking — from onboarding through to self-healing.
Configuration packages bundle checks, software and automations and apply automatically via rules
Build rules in plain language or write them in OQL, octoja's query language
Triggers: new device, schedule or manual start
Actions: run a script, install software, restart a device, send a webhook, post a Teams message, raise a ticket, set a tag, write a field
Conditions, variables from previous steps and defined behaviour on failure or when a device is offline
Test run and a complete execution history
Remote support & toolbox
Screen, terminal, files, registry and services in the browser.
Remote desktop with multi-monitor support, clipboard sync, file transfer and user consent
Interactive terminal (PowerShell, CMD, bash) with multiple sessions and saved commands
File browser with upload, download, ZIP, search and disk space analysis
View, start, stop and end services and processes live
Registry editor and filtered event log view
Active Directory tasks on domain controllers: create users, disable accounts, reset passwords
Wake-on-LAN via a neighbouring device at the same site
Inventory & documentation
Every change to the estate traceable — captured automatically.
Capture hardware, software, services, network adapters, shares, local accounts and groups automatically
Inventory history with change comparison: what changed, when and on which device
Windows licence keys and warranty information from selected manufacturers
Custom fields for devices and customers, automatic tagging via rules
Export as CSV, import from existing documentation tools
Virtualisation & network
ESXi, vCenter, Hyper-V and firewalls — not just monitored, but controlled.
Connect VMware ESXi and vCenter: list virtual machines, power them on and off, review host performance
Create and roll back snapshots from the interface — without opening the vSphere client
Hyper-V with host health and the status of individual virtual machines
Manage firewalls as fully fledged devices: OPNsense, Sophos XG, FortiGate, WatchGuard, SonicWall, Securepoint UTM, Check Point and others
Depending on the model, also throughput per interface, open sessions, VPN state, HA status, firmware currency plus CPU and memory utilisation
Switches, access points, printers, NAS systems and UPS units in the same estate — with no agent at all
Wake-on-LAN via a neighbouring device at the site when the target device is switched off
White label
Your branding — from the login screen to the agent and the customer PDF.
Your own product name and window title instead of “octoja”
Brand and secondary colour, set separately for the light and dark interface
Your own logo and icon, each in a light and dark variant, plus your own mascot on the sign-in page
Your own domain for your instance, with guidance for the DNS records and an automatic availability check
The branding extends into the agent on the endpoint — your end customers see you, not us
Reports are generated and sent as PDFs in the same branding
Reporting & evidence
17 ready-made templates, around 40 widgets, scheduled delivery as PDF.
17 ready-made templates, including management summary, patch compliance, backup status, SLA and incident reports
Build your own reports by drag-and-drop from around 40 widgets with a live preview
Scheduled delivery to fixed recipient lists, per customer or site
Output as PDF in your own branding
Delivery history with the status of each run
Integrations & API
Ticketing systems, alerting with on-call rota, webhooks and an open API.
Ticketing and PSA systems: DocBee, TANSS, TOPdesk, c-entron, HaloPSA, Autotask, Jira Service Management, Freshservice, Inserve, Odoo and others
Documentation: Hudu, IT Glue, woasi
Security: Bitdefender GravityZone and Lywand vulnerability audit
Alerting via Microsoft Teams, email, signed webhooks as well as SMS, phone call, WhatsApp and app push
Notification groups with their own service hours per channel — into the ticketing system during the day, by phone call to the on-call engineer at night, with days and times freely configurable, including across midnight
Escalation based on failure rate rather than every blip: an alert only once a defined proportion of recent checks fails — by count or period, above a minimum severity
Alerts raised outside service hours are held back and delivered in the next window rather than being lost; all-clear messages always go through immediately
An alert latch per channel prevents alert floods, and on all-clear the ticket in the external system closes automatically
MCP server with graduated permissions so AI assistants can access the estate under control
Documented REST API with an open Swagger interface
The alert lands where your team already works.
An alert is only worth something once it reaches the right person at the right time — and closes itself again when the problem has gone.
Ticketing systems & PSA
Alerts raise a ticket where your team already works — and close it again on all-clear. Customer records can be imported.
- DocBee
- TANSS
- TOPdesk
- c-entron Service-Board
- HaloPSA
- Autotask
- Jira Service Management
- Freshservice
- Inserve
- Odoo Helpdesk
- Codemeta
Alerting
Separate service hours per channel. Into the ticketing system during the day, by phone call to the on-call engineer at night — alerts outside those hours are held back, not discarded.
- Microsoft Teams
- Signierte Webhooks
- SMS
- Sprachanruf
- App-Push
- Internes Ticket
Documentation & ITAM
The device estate is mirrored into your existing documentation rather than creating a second register.
- Hudu
- IT Glue
- woasi
- Jira Assets
Antivirus, EDR & vulnerabilities
Protection status and vulnerabilities come together in the same view as the rest of the estate — regardless of whose security software the customer runs.
- Microsoft Defender
- Bitdefender GravityZone
- SentinelOne
- CrowdStrike Falcon
- Sophos
- ESET
- G DATA
- Securepoint Antivirus Pro
- ThreatDown (Malwarebytes)
- Lywand Schwachstellenaudit
Backup — monitored across vendors
Firewalls & appliances
Hardware, storage and network without an agent
Server workloads
Not listed, but there
- Tenant separation right down to the database query
- 17 device action permissions, individually assignable
- Audit log across 26 object types
- Two-factor authentication via TOTP and sign-in via OpenID Connect
- Time tracking at the device, linked to the case
- Wallboard with an audible alert for the service desk
The permission and evidence model is best explained against your own structure.
Get trial accessThe quickest way to form a judgement
Request trial access, roll out the agent, look at your own devices. Everything else follows from there.